Public-repo privacy hardening. No functional changes.
After v0.1.1 went out, an external reviewer flagged three PII / metadata leaks that would have grown over time on a scraped index like PyPI. All three fixed before broader distribution.
What changed
- Author email on PyPI — personal Gmail replaced with GitHub no-reply (
192558850+alex-lamport@users.noreply.github.com). - PHILOSOPHY.md — §7 marked as decision-closed (
kaora-memoryconfirmed). §8 (references to private dev assets) removed. New "Block N" glossary added at the top. - Bulk repo scrub —
/Users/alexissilva/→~/everywhere inAGENTS.md,BACKLOG.md,docs/CURRENT_STATE.md,docs/SESSION_HANDOFF.md,docs/DOGFOODING_REPORT.md. Private asset filenames in/tmp/...replaced with generic placeholders.template/was not affected (it uses{{project_path}}). - AGENTS.md Owner line — personal Gmail removed (shipped in commit
4794ee4after v0.1.2 was already cut). Replaced with GitHub profile link. - DOGFOODING_REPORT.md — two reading notes for external readers: (1) Block N terminology, (2) Italian/English mix in cited commit messages is historical (pre-Block 4.5 i18n refactor), not stylistic drift.
Note on v0.1.1
v0.1.1 was withdrawn from PyPI on 2026-05-28 as part of this privacy hardening cycle. It was functionally identical to v0.1.2 — the only difference was the leaked Gmail in the package metadata. Anyone who installed 0.1.1 in the few hours it was live got the same code and template, just with stale author metadata. pip install kaora-memory resolves to 0.1.2 automatically.
Code & tests
No code touched in this release. Suite 68/68 green. kaora check . 0 ERROR / 0 WARN. twine check PASSED.
Install
pip install kaora-memory